CVE-2024-24755

MEDIUM

discourse-group-membership-ip-block - Info Disclosure

Title source: llm
STIX 2.1

Description

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields to the client, including group custom fields from other plugins which may expect their custom fields to remain secret.

Scores

CVSS v3 4.3
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
discourse/group_membership_ip_blocks
Published Feb 01, 2024
Tracked Since Feb 18, 2026